Vista Home Basic, No Internet connection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JRock10, Dec 22, 2011.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm trying to find a solution for this. It seems to work okay for XP systems but it appears this may be a common problem with Vista and Win 7 and I have not seen a definite solution. In the meantime please get the new MGtools updated just a few minutes ago and attach the new log. This will save some registry keys we may need to delete.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  2. JRock10

    JRock10 Private E-2

    ah, so this is becoming a learning process for both of us? I do appreciate all the help, as well.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now Click Start, then Run, and type cmd into the Run box and click OK. This will bring up the command prompt. Now enter the below commands the below into the command prompt window one at a time each followed by the enter key. Tell me EXACTLY why message you get for each

    netsh int ip reset resetlog.txt

    netsh winsock reset catalog

    Now no matter what has happened above, continue to do the below.

    Reboot your PC!!!!

    After reboot, see if you can follow those previous instructions where you were getting stuck because the Uninstall button was inactive.
     
  4. JRock10

    JRock10 Private E-2

    reg edit successful

    1st cmd: briefly opened the cmd window, then closed with no other actions

    2nd cmd: same as 1st cmd, cmd window opened and closed with no other actions

    rebooting now and will perform previous process
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. Not sure how much more I will be around tonight. And with tomorrow being New Year's Eve.... well who knows.;)
     
  6. JRock10

    JRock10 Private E-2

    still unable to uninstall tcpipv4

    computer is slower to respond to input now (mouse clicks, opening windows)
     
  7. JRock10

    JRock10 Private E-2

    hey, i understand completely! I really thank you for how far we've gotten to this point! It's been down for about 4 weeks already, so a few more days won't hurt. This is one of those, if you have time, great, if not, well that's alright, too. I have faith it will get fixed!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then I suggest that you uninstall your network adapter from Device Manager.

    • Open Device Manager ( press the Window Logo Key + the Pause key ) and select Device Manager
    • Open the Network Adapters section
    • Right mouse click on your network adapter and select Uninstall
    • When prompted, choose OK and let it uninstall.
    • If you are asked if you want to delete the driver software and files too, say No.
    • Now reboot your PC.
    • Upon reboot, it should redetect your hardware and hopefully reinstall the drivers.
    • Let me know if this works as described and whether or not it changes anything.
    Also download the current version ( updated again ) of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  9. JRock10

    JRock10 Private E-2

    took three tries, but the network adapter uninstall worked, and the computer did recognize and re-install the hardware. still no internet.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Manual steps to recover from Winsock2 corruption for Windows Vista users

    Winsock corruption can cause connectivity problems. To resolve this issue by using Network Diagnostics in Windows Vista, follow these steps:
    1. Click [​IMG] and then click Network.
    2. Click Network and Sharing Center.
    3. In the Network and Sharing Center box, click Diagnose and Repair.
    Note You may also access the Network and Sharing Center in Control Panel.


    Now Reset Winsock for Windows Vista

    To reset Winsock for Windows Vista, follow these steps:
    1. Click [​IMG] type cmd in the Start Search box, right-click cmd.exe, click Run as administrator, and then press Continue.
    2. Type netsh winsock reset at the command prompt, and then press ENTER.

      Note If the command is typed incorrectly, you will receive an error message. Type the command again. When the command is completed successfully, a confirmation appears, followed by a new command prompt. Then, go to step 3.
    3. Type exit, and then press ENTER.
    Now reboot your PC into safe mode. While in safe mode see if can follow those previous instructions to Uninstall Internet Protocol Version 4 (TCP/IPv4) Let me know what happens. No matter what happens, reboot back into normal mode and then do the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  11. JRock10

    JRock10 Private E-2

    the system cannot find the file specified for winsock reset in cmd window
     
  12. JRock10

    JRock10 Private E-2

    uninstall button acts the same in safe mode with networking as in normal mode.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are running out of options. We really need this button to work but I don't know of anyway to do that.

    Let's try something else, click hold down the Windows logo key while also pressing the 'e' key. This will open Windows Explorer. Navigate to the file and right click on it and select Install

    c:\windows\inf\nettcpip.inf

    What happens? Do the below no matter what happens.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  14. JRock10

    JRock10 Private E-2

    i was afraid of that, and i was also going to ask if there was a way for me to "backdoor" this protocol through explorer. let me try what you just suggested.
     
  15. JRock10

    JRock10 Private E-2

    ok, i can navigate to the file, right click to install, then then icons and screen basically refresh and that's it.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's change nettcpip.inf file back to having 0xA0 and try running it again.


    • Please click Start, and type cmd.exe into the search box
    • You should see a cmd.exe and icon appear in the Programs area of the Start Menu.
    • Right click on cmd.exe and select Run As Administrator
    • A command prompt window should open with a title of Administrator:Command Prompt.
    • Type the following in the command prompt window and then hit enter:
      • notepad c:\windows\inf\nettcpip.inf
      • (note that there is space after notepad)
    • The above file will open in the notepad.
    • Under [MS_TCPIP.PrimaryInstall] section find the following: Characteristics = 0x80
    • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
    • Under File menu click Save and close the notepad.
    • Now navigate to the c:\windows\inf\nettcpip.inf file and and right click on it and select Install.
    • Then reboot your PC.
    After reboot, reconfigure your PC to make sure you are setup to use DHCP ( that is Obtain an IP Address Automatically ) see http://uits.iu.edu/page/aiyy

    Make sure he Obtain DNS Server address automatically is also selected.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    If this does not help, I'm afraid that the only option left is to reinstall because I found out that, unlike in Windows XP, with Vista and Windows 7, you are not allowed to uninstall the IPv4 or IPv6 protocols. A supposed work around is running the below in an Administrator command prompt windows, but I don't believe these will work and we already really did these.

    netsh winsock reset catalog
    netsh int ipv4 reset resetlog.txt


    The only way I have seen the problem you are having get fixed is via the uninstall of
    the protocols and then a reinstall. Since this is no longer allowed in the newer
    operating systems, the only alternative is probably to reinstall Windows. Seems
    like a screw up on by Microsoft to change this behavior to me in not allowing these to be uninstalled. And now that malware has figured this out, everyone running Vista and Win7 are going to be in trouble if they get one of these infections.
     
  17. JRock10

    JRock10 Private E-2

    i haven't forgotten this, but we just had our newborn baby! i will get back to this issue soon, and i thank you for all the help thus far.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well congrats on the new member of the family! :)
     
  19. JRock10

    JRock10 Private E-2

    ok, did the last posted actions and here is the log
     

    Attached Files:

  20. thisisu

    thisisu Malware Consultant

    Congrats on the baby, JRock10 :)

    I will help you while Chaslang is away.

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:
    • Spybot - Search & Destroy
    • SUPERAntiSpyware

    __

    [​IMG] Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Register System Files
      • Repair WMI
      • Repair Hosts File
      • Repair Winsock & DNS Cache
      • Remove Temp Files
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    [​IMG] Now download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds